3.2 APEX update questions

Hi guys,.

I need to do a review on the benefits of upgrading to 3.2 and hoped for clarification on a number of things. The functionality of the Forms provides no use to us, so the point is on the [security changes | http://www.oracle.com/technology/products/database/application_express/html/3.2_new_features.html].

Declarative encrypt session state
Declaratively specify wait times of session for the maximum idle time and the maximum duration of session
What do these? That means declaratively they user MUST specify? Why are they useful? What were they like before?

New element types create password that allow users to enter passwords without ever saving their session state - why is it useful? Saves the State of session a security problem? Why it would take up to 3.2 for it be changed then: o
Reduce the footprint exposed by reducing the privileges required by the Oracle Application Express database account - does that mean? Foot print?
Deactivation of the service of default data monitor - if this refers to the activity of users monitor etc then why is - this good? Looks extra hassle for the admins see what users do
Allowing administrators to require HTTPS for administration and enforcement on development - administration and development suite applications?
Service Administrator account passwords are consistent with a strong password policy - trying to cause me trouble when deciding on a password?

Anyone know of any other addition in addition to what is mentioned here? for example new articles, reports, themes etc.

Thanks for help.

Mike

Mike,

Some of your comments seem a bit antagonistic such as "why it would take up to 3.2 for it be changed then: o ' and 'try to cause me trouble when deciding on a password?'. It is not the best way to get answers to the questions.

Declarative encrypt session state

For any element that can contain sensitive data, you can say APEX to encrypt it while it is stored in the tables of State meeting of the APEX. This prevents a sys_admin to query this table and entered these values. It also keeps them out of the redo log files, etc. However, you should always deal with encryption of sensitive data when you save to your tables.

Declaratively specify wait times of session for the maximum idle time and the maximum duration of session

You can change a parameter indicating the sessions expire after x minutes. Declarative means there are a graphical interface, do not do it in the code.

Create item types that allow users to enter passwords without ever saving to session state new password

Yes, saving it session state is a security problem as a system administrator may seek in the session state tables.

Minimize the exposed footprint by reducing the privileges required by the Oracle Application Express database account

APEX requires less privs to run to access schemas APEX gives a hacker less energy. Think of it as SYS vs SCOTT. If you broke into the SCOTT schema, there not much damage, that you could do. However, if you walked into SYS, you could do what you wanted to do in the database.

Disabling the default data monitor function

This isn't the user monitor section, this is a section that allows you to display the top sql, sessions, etc. Yes, it's more complicated. It's more of a hassle for me to lock my door when I leave, but I always do.

Service administrator account passwords are consistent with a strong password policy - trying to cause me trouble when deciding on a password?

Let me guess, your sys / system / root / admin password is one of the following values: sys, Manager, change_on_install, oracle, host, password, enter, root, qwerty, 12345? ;)

Tyler Muth
http://tylermuth.WordPress.com
[Oracle security application: development of secure database and Middleware environments | http://www.amazon.com/gp/product/0071613706?ie=UTF8&tag=tylsblo-20&linkCode=as2&camp=1789&creative=9325&creativeASIN=0071613706]
! http://www.Assoc-Amazon.com/e/IR?t=tylsblo-20&l=AS2&o=1&a=0071613706!

Tags: Database

Similar Questions

  • Apex 4 or 5 zoom function and macros and update questions

    Presently, got open users in Excel via odbc tables and I want to transfer to Apex.

    1. How can I reduce the Apex down police according to the Excel zoom feature so that more data gets to the screen.   I want a LOT of data on the screen, Ive got some end users who wish to up to 100 + rows and columns of 30 +, they don't mind the size and readability, the screens are big and have macros that are constantly highlighting changes to data they are interested in what brings us to question 2

    2. how macros script to Flash color changes.

    3. how data streams constantly modify data in a table live the Apex report and apply these macros.   Refresh rate?

    IM in dev with version 4, but if a feature isn't available until the level 5 I can hold off.

    Hello

    All the above mentioned requirements can be done in one of the APEX, version 4 or 5.

    1. it is a change of POLICE CSS based on the model of HTML page, and it is supported in the APEX 4 and 5 times.

    2. for changes from flashing color macros (formulas), you should design your SQL query and insert various HTML tags in SQL query results.

    3. updating of the page tables, can be programmed using jQuery functions.

    So, basically we expect 5 APEX as your condition does not use what is explicit to APEX 5.0 /.

    Thank you

    Sunil Bhatia

  • Windows 8.1 update questions about the Satellite P870 - PSPLFA

    Hello

    For the better or worse over the weekend, I downloaded windows 8.1 on a toshiba laptop (model PSPLFA p870) that was running windows 8. Graphics card is NVIDIA® GeForce® GT 630 M 2 GB with Optimus + Intel® HD Graphics 4000

    http://www.MyToshiba.com.au/support/computers/satellite/p870/psplfa-019001/specifications

    couple of questions:

    (a) I'm having some trouble to make windows 8.1 works fine on this laptop and cannot get/find new drivers on the toshiba site to properly adjust the video card.

    Any ideas how or where I can download video drivers that are suitable for this laptop?
    Too eager not to uninstall and go back to windows 8, now that I went that day...

    I have a call yesterday with microsoft yesterday which seems to go nowhere to fix one or two other things after this upgrade.

    (b) on the windows 8.1 machine my internet connection when running IE11
    seems now a little flaky and suspect that it is a matter of 11/windows 8.1 internet explore (other laptops on my wireless network running windows 7 and XP work fine and do not abandon their studies and can access all the info I can't get on the machine win 8.1) which seems to be a bit a common issues by looking at some other forums and

    (c) I can't download or open files from google docs (screen freezes right most of the way through the download) on the 8.1 update windows machine.

    Any help appreciated,
    Ken

    Hello

    Your laptop belongs to the PSPLFA series. This series was released in Australia

    The same notebook PSPLFE series is available in Europe.

    On the page of the Toshiba UE driver you will find all drivers update 8.1 Win
    http://www.Toshiba.EU/innovation/download_drivers_bios.jsp?service=EU

    _Importnat: _ the Win 8.1 drivers must be installed in the right order!
    Check the instructions for installation, which is available in the list of drivers too and follow exact order!

  • HP ENVY 17 t-k000 CTO laptop: HP ENVY 17 t-k000 CTO Notebook PC (ENERGY STAR) Bios Update Question

    My Hp Support Assistant wants me to update my bios...

    I have two questions regarding this.

    1. the software to Flash the bios is not compatiable with windows 10.  It will be safe to run anyway? (Yes, I have installed a free update to windows 10)

    2 sp71055.exe f42.ap1 (corresponds to the file, it is recommended to run to my i7 from intel, patch notes (always never enough information) provide that it restores or that it provides the original bios.)

    My bios version connected is

    BIOS version / date f/34. 12-19-2014

    On a previous occasion, I thought I already flashed the bios and I was wondering if I need to restore to the original version, or it turns out is a bit 'off '.

    The link you have provided updated the bios with no ill affects (for now!) Thank you for your help

  • BIOS update question

    Hi, I recently got a ThinkCentre M52 8113-E7U TC series

    My question is about the BIOS update.

    If I update to the latest version, this is includes all fixes from previous versions?

    I noticed, that I can not boot from USB more than flash drives 2 GB, I see it as a fix in an update of the earlier BIOS, so if I update to the latest version of BIOS will it also include this fix?

    Thank you

    Rick

    Hello and welcome,

    The BIOS updates are cumulative and include previous fixes and improvements.

    Z.

  • Wifi Hotspot after Lollipop 5.0.2 update questions?

    Hi all

    I would like to know if anyone has any questions of wifi hotspot after Lollipop 5.0.2 update. I can't share my internet connection phone, hotspot is there, computer laptop to connect but I can not load Web sites. Strangely, I can use Skype, but that's all. I have the same problem with USB Bluetooth ICS and as well. Did somebody encounter this problem? Thank you.


  • Richard & update questions about the Pavilion M8407

    I just put in an order for a Pavilion M8407C PC.  I ordered the PC because it is a quad-core, running a 64 bit OS and the price was so right.  I am interested in building a box fairly high-end at about 6 to 9 months, but need something now because my box 5 years just has no power for my applications anymore.

    I'll use it for modeling 3D and 3D engineering applications in the short term, and it will become a long term rendering area.

    Issues related to the:

    (1) the PC has 4 GB or RAM of 1 Gb Simms.  I'll upgrade to 8 GB, he would like to know if it is able to use 16Gb.  The OS is Vista Home Premium - is limited to 8 GB or 16 GB?  Is the limit of the 'House' or 'premium '?

    (2) the PC contains 2 360 GB drives.  Are they "RAID" ed or only 2 separate units (master & slave)?  All programs would be installed on a disk or both?  The second disk can be replaced with a larger without any OS or system of the impact?

    (3) how can be upgraded on the PC?  The operating system at any time will stop working because too many things have changed from the original HP Setup?

    Thanks for the review - I'm pretty comfortable with a screwdriver and have been building my own boxes, I'm not too familiar with the way in which 'Tier 1' PCs are set up.

    See you soon...

    Message edited by Matthew on 03/12/2008 19:49

    For someone who cares, I have rebuilt the box and here are the answers to my previous questions...

    (1) limit of motherboard memory is 8 GB.

    (2) the 2 360 GB disks are not attacked.  disk 1 is the 'OS' and 'HP install' backup and the second disc is empty.  This is ideal, because all OS and programs can be installed on the operating system drive, and the second player can be offered for data.  Easy for backups.

    (3) I have considerably improved the system.  You cannot change the motherboard, that would invalidate the Windows operating system installation.  MS wrote on OEM computers, changing motherboards is paramount to junking the old computer and requires a new purchase of OS.  I think they make exceptions for warranty cards mothers replacement - better double-check.

    I've updated...

    (A) memory.  Replaced the 4 GB (1 GB simms) with 8 GB (2 GB simms).  Simms spare parts become old.

    (B) added a 1 TB drive.  The chassis has room for 2 hard drives.  I added the third disc to his empty home of 5.25 "under the DVD drive.  I had to use a kit of adaptation and screws washers to fix the kit on the sides split to create a good grip.

    (C) replace the video card.  The NVidia 8500GT has of one taken DVI and HDMI output.  I couldn't get a good Monitor 2 out of it, because my monitors have entered VGA only.  In addition, I wanted a 1 GB of memory on the card as the programs I run use large textures so need more video of 512 MB of ram.  Replaced the with a NVidia GTS250 1 GB 8500GT.

    (D) the updates above, especialy video card, required a higher power supply.  I replaced the original 300W with a 650W unit.

    (E) the M8407C system comes with a slot to accept a "HP Personal Media Drive" unit.  Recently, I received an email from Best Buy, which featured a HP Personal Media Drive unites 750 GB on sale for CAD$ 110.  Sold. Removable data backup unit.

    To summarize, for a total investment of just under $ 1100, I created a Quad Core, 8 GB ram, disk hard system of 2.4 to pushing the 2 monitors.  The goal was to build a system capable of modeling 3D and animation for cheaper than buying the parts off the shelf.  I saved CAD $700 and have spare parts to help build a render region.

    Message edited by James on 10/04/2009 14:25
  • Premiere Pro launches more after the update, question mark on the icon appears

    I've just updated Premiere Pro, and now it launches more. Only a question mark on the icon appears. The same thing happens with Illustrator, After Effects, and Photoshop. Does anyone have an idea on how to fix this?

    Screen Shot 2016-06-25 at 19.28.56.png

    I thought about it. I just reinstalled all my apps that wouldn't launch and it works fine now. You can simply uninstall the apps screen update CC and then install here once again.

  • Update question Installation Manager

    Our vCenter4 server is on a 64 bit Windows 2008 Server.    I just read the VUM Administrator's guide and if you don't catch the sentence x 86 you you could install on Windows 2008 (as it says you can, but I think that means the 32-bit version).   So if I'm wrong, then my desire to install on my server vCenter Update Manager is down the tubes.    So now, I'm stuck between a rock and a hard place.   My question is: can I create a virtual machine with Windows XP SP2 and install Vmware Update Manager on the virtual machine.  I don't have any physics more servers or workstations to devote to this effect.   Or I am mistaken and I should be able to install on 64-bit hardware?

    According to the vSphere compatibility charts on page 17, he says VUM may be installed on 2008 x 64

  • characterset apex listener questions

    Hello forum help,

    I have a problem with the character set when you use the earpiece of the apex and the database oracle under windows.

    My environment in the registry (HKLM/SOFTWARE/ORACLE/HOME) is NLS_LANG = GERMAN_GERMANY. WE8MSWIN1252

    My value in the database is:
    SQL > select aufgabe dhw.auftraege where auftragsnummer = 23;

    AUFGABE
    -----------------------------------------------------------------
    Turendrucker

    My desription of connector in tomcat's server.xml file is
    < connector port = "8080" protocol = "HTTP/1.1".
    connectionTimeout = "20000".
    maxHttpHeaderSize = '32767 '.
    URIEncoding = "UTF-8" / >

    Is my description of filter in the Web.XML of my apex installation (as described in another thread)
    < filter >
    Coding of characters defined < filter-name > < / filter-name >
    < class filter > filters. SetCharacterEncodingFilter < / class filter >
    < init-param >
    < param name - > encoding < / param-name >
    UTF8 < param-value > < / param-value >
    < / init-param >
    < / filter >
    < filter mapping >
    Coding of characters defined < filter-name > < / filter-name >
    < url-pattern > / * < / url-pattern >
    < / filter-mapping >

    But the result on the Web page is:
    T_rendr_cker (underscores value is initially a small square)

    How can I solve this problem?
    What character parameters will be valid to show the same data on the html page, as recorded in the database?

    Thanks for the reply!

    Concerning

    Frank

    Hi Frank,.

    you might want to ask the following question in the [url http://forums.oracle.com/forums/forum.jspa?forumID=858] Forum listener APEX.

    brgds,
    Peter

    -----
    Blog: http://www.oracle-and-apex.com
    ApexLib: http://apexlib.oracleapex.info
    BuilderPlugin: http://builderplugin.oracleapex.info
    Work: http://www.click-click.at

  • Apex SQL question - weeks of the month

    I have a sql question.
    I want to create a dynamic list.

    If the user select may2009, then I want a dynamic list of show

    04/27/2009-05/03/2009
    05/04/2009-05/10/2009
    05/11/2009-05/17/2009
    05/18/2009-05/24/2009
    05/25/2009-05/31/2009

    If the user selects Jun 2009, then the list will be
    06/01/2009-06/07/2009
    06/08/2009-06/14/2009
    06/15/2009-06/21/2009
    06/22/2009-06/28/2009
    06/29/2009-07/05/2009

    Thank you.

    Using this SQL statement, you can get this list:

    SELECT w_start || ' - ' || w_end d, w_start r
      FROM (SELECT     (week_start_list + (LEVEL - 1) * 7) + 1 w_start,
                       week_start_list + (LEVEL) * 7 w_end
                  FROM (SELECT TO_CHAR (TRUNC (TO_DATE (:my_date, 'dd.mm.yyyy'),
                                               'mm'
                                              ),
                                        'IW'
                                       ) week_begin,
                               TRUNC (TO_DATE (:my_date, 'dd.mm.yyyy'),
                                      'mm'
                                     ) m_begin,
                               TO_CHAR
                                  (TRUNC (TO_DATE (:my_date, 'dd.mm.yyyy'), 'mm'),
                                   'd'
                                  ) day_month_begin,
                               TO_CHAR
                                  (TRUNC (ADD_MONTHS (TO_DATE (:my_date,
                                                               'dd.mm.yyyy'
                                                              ),
                                                      1
                                                     ),
                                          'mm'
                                         ),
                                   'IW'
                                  ) week_end,
                               TRUNC (ADD_MONTHS (TO_DATE (:my_date, 'dd.mm.yyyy'),
                                                  1
                                                 ),
                                      'mm'
                                     ) m_end,
                               TO_CHAR
                                  (TRUNC (ADD_MONTHS (TO_DATE (:my_date,
                                                               'dd.mm.yyyy'
                                                              ),
                                                      1
                                                     ),
                                          'mm'
                                         ),
                                   'd'
                                  ) day_month_end,
                                 TRUNC (TO_DATE (:my_date, 'dd.mm.yyyy'),
                                        'mm'
                                       )
                               - TO_NUMBER
                                          (TO_CHAR (TRUNC (TO_DATE (:my_date,
                                                                    'dd.mm.yyyy'
                                                                   ),
                                                           'mm'
                                                          ),
                                                    'd'
                                                   )
                                          ) week_start_list,
                                 TRUNC
                                    (ADD_MONTHS (TO_DATE (:my_date, 'dd.mm.yyyy'),
                                                 1
                                                ),
                                     'mm'
                                    )
                               + TO_NUMBER
                                    (TO_CHAR
                                        (TRUNC
                                              (ADD_MONTHS (TO_DATE (:my_date,
                                                                    'dd.mm.yyyy'
                                                                   ),
                                                           1
                                                          ),
                                               'mm'
                                              ),
                                         'd'
                                        )
                                    )
                               - 1 week_end_list
                          FROM DUAL)
            CONNECT BY LEVEL <=
                          (SELECT   TO_NUMBER
                                       (TO_CHAR
                                           (TRUNC
                                               (ADD_MONTHS (TO_DATE (:my_date,
                                                                     'dd.mm.yyyy'
                                                                    ),
                                                            1
                                                           ),
                                                'mm'
                                               ),
                                            'IW'
                                           )
                                       )
                                  - TO_NUMBER
                                          (TO_CHAR (TRUNC (TO_DATE (:my_date,
                                                                    'dd.mm.yyyy'
                                                                   ),
                                                           'mm'
                                                          ),
                                                    'IW'
                                                   )
                                          )
                             FROM DUAL))
    

    It is a question of SQL and has nothing to do with the Apex.

    Denes Kubicek
    -------------------------------------------------------------------
    http://deneskubicek.blogspot.com/
    http://www.Opal-consulting.de/training
    http://Apex.Oracle.com/pls/OTN/f?p=31517:1
    -------------------------------------------------------------------

  • Apex Newbie question!  HTTP Server?

    I'm newbie at the APEX. I have a background, s/n, but no experience with Oracle applications.

    I respect your time and tried to find this info on the docs, but, honestly, can't find it. And I looked everywhere, metalink, otn, gogling. I thought I'd find on these forums a form any of the FAQ, but have not found the answer :-(

    I installed the oracle 11g for windows database on my laptop, and when you install APEX 3.2, it asks me to stop the http server and... :-)

    Now, I have a question about the Oracle HTTP server, which is supposed to be isntalled with 11g, rather than the accompanying CD, that exist no longers.

    First question. We have a http server which is used by oracle control EM database, correct? I don't see a service for her on the list of Services. Installation of teh apex application requires the http server start/stop. How do we proceed? AND where the binaries of the http server located? I did a search for apache and found under C:\app\oracle\product\11.1.0\db_1\perl\site\5.8.3\lib\Apache, but not binary here, or under the ORACLE_BASE\bin either.

    That set up for windows environment ORACLE_HTTPSERVER on a brand new installation of database 11g?

    Now I see that we can get from Server HTTP installation of BEA. I was trying to prevent APEX to use a level of web server here. For me, the beauty of the APEX is not having to manage the BEA, or any other level. Keep it simple, at least for the development and keep everything on the DB, just use the native HTTP server.

    It is therefore a VERY fundamental, but how do I do this? Worries me what I can and can't do with the native HTTP server or BEA later. I just want to get this site up and running so that I can start playing with it.

    Thank you

    Henrique

    Henrique

    Looks like you can simply use the PL/SQL gateway incorporated in the database so far, but all this information is available here:

    [http://download.oracle.com/docs/cd/E14373_01/install.32/e13366/overview.htm]

    See you soon

    Ben

  • IPhone 6 IOS update question

    I have updated to the latest update of IOS and I encountered a problem.  When the phone restarts, he invites me for a password.  The problem with this is there was no access programmed into the phone just the finger print ID code  I tried different passwords strengthened and not worked.  So the next step of the process, I put the phone in recovery mode and connected to ITunes and ITunes says that there is a problem with the update of IOS and begins to resettle the IOS.  When the phone restarts, I get the necessary access code and then I start the recovery process.  The recovery mode is stuck in a loop on Dungeon reinstall IOS and asking me to specify a password.  Any ideas on how I can break the loop?

    Are you sure he doesn't ask you to set a password?

  • Firefox is unbearably slow after update (/ questions/985969)

    Firefox slows and raises my CPU at 100% after a few hours of use. This happened again and again after that I updated Firefox Versions 27, 28 and 29 now. If I restart my computer, Firefox works normally for a while before it slows down again. Same text by tapping on my e-mail slows down to a crawl.

    The 3 modules I have are the following: -.
    (a) Edge Adblock 2.1.1
    (b) download videos from Youtube in MP4 1.7.18
    (c) McAfee SiteAdvisor 3.7.0

    It is a serious problem and a game changer for Firefox. I hope that experts in Firefox will fix this bug soon. Meanwhile, if there is a solution to this problem, someone would share its solution in this thread please?

    Launch Firefox in Mode safe

    While you are in safe mode; Firefox Options > advanced > General.

    Find and stop using hardware acceleration.

    Dig safe web sites and see if there is still a problem. Then restart.

    It could be the work of one of your modules, or even add / bad-ware.
    Look through your list of modules and make sure you know what each of them is
    and so. In addition,
    check the programs that are on your computer
    Windows > start > Control Panel > uninstall programs.
    Go through the list and a web search to check that you have not
    know what they are.

    Fix Firefox problems caused by malicious software

  • Satellite M40x-189: on the HARD drive and graphics card update Question

    Hi people just a few quick questions.

    1. a second hard drive can I be mounted on the cell above?... it came with a 60 GB HARD drive
    graphics mobile geforce or ati 2. can / will be mounted instead of the integrated graphics card?

    the answers would be greatly appreciated.

    Hello

    It is not possible to upgrade or replace the graphics card. The graphics card is a small chip that attaches to the motherboard. It s not the same technology as on desktop computers.
    Upgrading the HARD drive is something different. It of possible to replace the HARD drive to another. But before you replace the HARD drive, you must check if the HARD disk is compatible and if the BIOS will recognize.
    Sometimes the BIOS cannot recognize the hardest.

    Good bye

Maybe you are looking for

  • FireWire and Tecra S1

    Hi, can someone tell me if it is possible to use the FireWire port on a docking station, although the S1 is not a fireWire port?

  • HP Officejet 8610: Cut 2 sided copy printer interface

    I need help turning off two-sided copy using the inetrface on the printer. I have no problesm but cpying printer problems. If I print two pages in two original copies, the printer wants to enter the page firstcopied and pull of iut in the printer to

  • Receipt of the possible scam email virus attached in Vista

    He was supposed to be sent to my son, his speeches, but he is only 14 years, isn't working, and he swears that he didn't send it. I know it didn't. Suspected Ive someones been in our accounts for a long time. but nobody is listening. in any case, I n

  • Creative sound blaster live model ct4780 driver for windows 7 32-bit

    I need creative sound blaster live model ct4780 driver for windows 7 32 bit driver can any body help me?

  • Help the Site VPN Site PIX 501

    Hello I'm pretty new to PIX firewall, so I hope someone here can help me. I have two PIX and try to create a private network virtual between the two PIX. I posted the configs below. The problem is that I can ping PIX on a PIX two, but I can't ping th